Printer RCE
A documented Canon MF753Cdw chain combines unauthenticated BJNP memory placement with a fax-job arbitrary free to execute shellcode from the LAN.
Canon says updated firmware corrects the flaw but does not name an exact version for this model in its US notice.
Sources
ResearchZero Day Initiative — CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printerVendorZDI-24-095 - TrendAI™ Zero Day Initiative™ (ZDI)VendorService Notice: Regarding Vulnerability Measure Against Buffer Overflow for Laser Printers and Small Office Multifunctional Printers | Canon U.S.A., Inc.